MOVEit Transfer Critical Vulnerability CVE-2023-34362 Rapid Response
ID: 8daebe8c-41c5-5e9b-b641-1b775ab11543
STIX ID: report--8daebe8c-41c5-5e9b-b641-1b775ab11543
Feed Name: Huntress Blog
Huntress reports active exploitation of critical SQL injection vulnerabilities in the MOVEit Transfer application (CVE-2023-34362 and CVE-2023-35036) that allow unauthenticated attackers to gain admin-level access, execute arbitrary code (including deploying a human2.aspx webshell and compiled ASP.NET DLLs), exfiltrate data, and detonate cl0p ransomware; the report contains timelines, IOCs (file paths and IPs), detection guidance (YARA and Sigma rules), registry locations for investigation, and mitigation recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
